← Insights / Compliance

The EU AI Act Is Already in Force. Your Legal Team Needs to Know What That Means Right Now.

There is a version of this conversation happening in boardrooms and legal team Slack channels across the world: someone has read that the EU AI Act's high-risk provisions don't fully apply until late 2027, and has concluded that the Act is, for practical purposes, still on the horizon. That conclusi

Compliance 8 September 2026 6 min read

The EU AI Act Is Already in Force. Your Legal Team Needs to Know What That Means Right Now.

There is a version of this conversation happening in boardrooms and legal team Slack channels across the world: someone has read that the EU AI Act's high-risk provisions don't fully apply until late 2027, and has concluded that the Act is, for practical purposes, still on the horizon. That conclusion is wrong, and acting on it carries real regulatory risk.

This post sets out what is actually in force, when the remaining obligations arrive, and — critically — why the distinction between being a provider and being a deployer under the Act may be the most important compliance question your firm hasn't formally answered.


What Is and Isn't Delayed

The EU AI Act entered into force in August 2024. It did not all become applicable at once. The regulation operates on a phased timeline, and the phase most organisations are misreading is the one covering high-risk AI systems.

Provisions governing prohibited AI practices became applicable first. The governance framework — including the requirement for member states to designate national competent authorities with supervisory and enforcement powers — followed. Those authorities exist. They have powers. The enforcement infrastructure is not waiting for 2027 to be switched on.

The extended timeline for certain high-risk AI system obligations gives providers and deployers in those categories additional time to achieve full compliance. It does not suspend scrutiny, and it does not affect obligations that were already applicable before that transition period began. If your firm is operating AI systems that touch prohibited categories, or if you are already subject to obligations that attached before the grace period, the later date for high-risk systems is not a shield.

For professional services firms advising clients internationally — law firms, consulting practices, accountancies, financial advisory businesses — this matters because many of you are not passive observers of the Act. You are, in legal terms, either providers or deployers of AI systems within scope.


The Provider/Deployer Distinction Is Not a Technicality

The EU AI Act places materially different obligations on providers — those who develop or place AI systems on the market — and deployers — those who use AI systems developed by others for a specific purpose. Deployers carry real obligations, but providers carry considerably heavier ones: conformity assessments, technical documentation, registration in the EU database, post-market monitoring, and more.

The trap that engineering and product teams in particular have not always mapped is the requalification risk. If your organisation takes a third-party foundation model and fine-tunes it on proprietary data — client files, financial records, sector-specific training sets — you may no longer be a deployer of someone else's system. Depending on the degree of modification and the purpose of the deployment, the Act's framework can requalify you as a provider, with the full provider obligations attached.

The same logic applies if you white-label or rebrand an AI system and place it in front of clients under your own name. Presenting a system as your own product, even if the underlying model was built elsewhere, triggers scrutiny of whether you have assumed provider responsibilities.

This is not a hypothetical edge case. It is the normal commercial pattern for a significant number of professional services AI deployments: a firm licenses a capable model, adapts it to their practice area, and surfaces it to clients as their own tool. That workflow, without careful legal analysis, can silently shift your regulatory classification.


Why This Is a Global Compliance Issue, Not a European One

International professional services businesses cannot treat the EU AI Act as someone else's problem simply because their headquarters sit outside the EU. The Act applies based on where AI systems are used and where their outputs have effect — not exclusively where the provider is incorporated.

A firm headquartered in Singapore, the United States, or the United Kingdom that deploys AI systems used by EU-based clients, or that processes data from EU individuals in automated systems with real-world consequences, is within scope of the Act's requirements in ways that are not resolved by geography alone.

Simultaneously, many of the same firms are navigating an expanding patchwork of national and regional AI obligations. The United Kingdom is developing its own sector-based AI governance framework. Several jurisdictions in Asia-Pacific are progressing AI-specific legislation. The United States has a complex mix of sector-level guidance and state legislation moving in parallel. Canada has no federal AI statute at all — Bill C-27, which carried the Artificial Intelligence and Data Act, died in January 2025 when Parliament was prorogued — so PIPEDA and provincial law, notably Quebec's Law 25 and Ontario's O. Reg. 476/24, carry the obligations there instead. Brazil has advanced AI legislation through its legislative process.

Operating across multiple jurisdictions means that no single compliance posture covers everything, and that the EU AI Act — despite its breadth — is one layer of several that international firms need to map and manage coherently. The provider/deployer question under the EU framework, for example, has analogues in other regulatory regimes. Getting the classification wrong in one jurisdiction often signals an analytical gap that replicates itself across others.


What Professional Services Firms Should Do Now

The practical steps are not exotic. They require rigour and cross-functional input, but they are achievable.

Map your AI systems with legal input from the start. An inventory that only engineering or operations teams produce will miss the classification questions. Every system your firm uses or offers to clients needs to be assessed for where it sits in the regulatory framework — not just whether it functions correctly.

Assess modification and white-labelling arrangements specifically. If your firm has customised any third-party model or is marketing an AI capability under your own brand, that arrangement needs formal legal review against the provider definition. The requalification risk is real and needs to be consciously ruled in or out, not assumed away.

Do not anchor compliance timelines to the latest applicable date in any single framework. Enforcement powers are active now under the EU AI Act. Other jurisdictions are moving. Treating a grace period for one category of obligation as a general delay to compliance activity is the reasoning error that creates regulatory exposure.

Treat jurisdictional variation as a structural compliance challenge, not a series of one-off projects. International firms need a compliance architecture that can accommodate multiple frameworks simultaneously, with clear ownership, documentation, and review cycles. Ad hoc responses to individual regulatory developments do not scale and do not hold up under regulatory scrutiny.


The Cost of Getting This Wrong

Regulatory penalties under the EU AI Act are significant. More immediately, for professional services firms, the reputational and contractual consequences of a compliance failure — particularly one that affects client-facing AI systems — are substantial. Clients in regulated industries are increasingly asking for AI compliance assurances as part of procurement and vendor due diligence. The firms that cannot answer those questions clearly will lose mandates to those that can.

The question being asked in public — is the AI Act really in force now? — deserves a plain answer: yes, in material respects, it is. The window for treating this as a future concern has closed.


Work With Ops Intel

Ops Intel writes AI compliance frameworks for small and medium businesses worldwide — accountants, solicitors, agencies and consultancies working across more than one jurisdiction — including clear-eyed assessments of provider versus deployer status, documentation frameworks, and readiness reviews against active regulatory obligations.

If your firm is navigating the EU AI Act, parallel national frameworks, or both, contact the Ops Intel team to discuss how we can support your compliance work.

Follow us in Google

See Ops Intel first when AI rules change

One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit